AI Attacks Demand an Access Review
An attacker doesn’t need weeks anymore
A recent report described AI agents breaching a company network in under 10 hours and obtaining root credentials. The point isn’t that every financial advisory firm faces that exact sequence tomorrow morning. The point is that the old security assumptions are failing.
An attacker used to need patience. They had to write convincing phishing emails, probe systems one by one, test credentials manually, and work slowly enough to avoid detection.
AI can compress much of that work.
It can draft client-like emails based on public information. It can test exposed systems faster. It can sort through stolen documents for credentials, organisation charts, client details, and software references. It can identify the best next move after getting a foothold.
For a financial advisory or wealth management firm, that should trigger a practical question.
Who can access your critical systems today, and what can an AI-connected tool reach if one employee account is compromised?
That question goes beyond your IT administrator. It includes advisers, paraplanners, client service staff, contractors, outsourced compliance support, and the software integrations that sit between your systems.
Most firms in the USD 1M to USD 25M revenue range haven’t deliberately designed this access structure. It has grown over time.
A new adviser joins and gets broad CRM permissions because it is easier. A departing staff member retains access to a shared folder. A third-party assistant keeps an old login. An AI note-taking product gets permission to read calendars, meeting recordings, or cloud documents. A shared admin account exists because an urgent task had to get done on a Friday afternoon.
None of those decisions feels reckless in isolation. Together, they can create an easy route from one stolen credential to client data, advice documents, portfolios, or firm-wide administration.
The first step isn’t to ban AI tools. It is to review access before you give more systems the ability to act.
See Omni for financial advisory firms if you want a structured way to identify where automation can create value without creating unnecessary exposure.
The access problem inside a typical advice firm
Financial advisers handle data that attackers value. Names, addresses, identification documents, bank details, trust structures, portfolio information, retirement balances, insurance records, risk profiles, and signed advice documents all sit somewhere in the operating stack.
The stack often includes:
- A CRM containing client relationships and communications
- Portfolio management or reporting software
- Document storage with SOAs, ROAs, file notes, and signed forms
- Email and calendar platforms
- Meeting recording and transcription tools
- Workflow tools used by paraplanners and client service teams
- Accounting, billing, and payment systems
- Identity providers and password managers
- Remote access tools managed by internal or external IT
Now add AI.
A meeting assistant may connect to every adviser calendar. A transcription product may store client discussions. A document-drafting tool may read template folders and upload outputs. An AI research assistant may have browser access or a connection to a shared drive. A workflow agent may need to create tasks in the CRM and send reminders from a mailbox.
These tools can be useful. They can also become a multiplier for a compromised user account if access is too broad.
The risk isn’t limited to someone breaking into an AI vendor. A standard phishing attack against an employee can become more damaging when the compromised account has connected applications, saved browser sessions, API tokens, or permissions that reach across several systems.
This is why privileged access matters so much.
A privileged account can change permissions, install software, access security settings, create new users, reset passwords, alter records, or access data outside the employee’s usual role. Root credentials are the clearest example, but high-risk permissions exist well below root level.
A client service manager with broad document access. An adviser with unrestricted CRM export permissions. A paraplanner account that can open every advice file. A shared Microsoft 365 administrator login. Each deserves scrutiny.
Start with the accounts that can do the most damage
An access review should not turn into a 200-row spreadsheet that no one acts on. Start with accounts and connections that can change the environment or expose large volumes of client data.
For most advice firms, review these five areas first.
1. Administrative and privileged accounts
List every administrator account across your identity provider, email platform, document system, CRM, network, portfolio system, and security tools.
Ask:
- Is this account tied to a real person?
- Is it used only when administrative work is required?
- Does the account have phishing-resistant MFA enabled?
- Is there a separate day-to-day account for normal work?
- Would anyone notice if this account logged in from an unfamiliar device or location?
- Is a former employee, IT contractor, or vendor still able to access it?
Shared admin accounts are a common weak point. They make audit trails unclear and make offboarding harder. If something goes wrong, you can’t confidently establish who performed an action.
For a small firm, separating administrator access from daily email and document work is one of the most practical controls available. An employee should not be reading client emails in the same account they use to manage firm-wide settings.
2. Dormant users and former staff
Firms often find old accounts during an access review. They belong to advisers who left, maternity cover staff, outsourced paraplanners, former managed service providers, or trial users of a software product.
Some are disabled. Others are still active because the offboarding process was informal.
Check active users against your payroll, contractor list, and current vendor list. Then check accounts that have not logged in for 30, 60, or 90 days. The exact threshold depends on the role, but an unused active account deserves an explanation.
Also look for shared accounts such as admin@, advice@, or operations@. There may be a valid business reason for a shared inbox. There is rarely a good reason for several people to share the same privileged login.
3. Application connections and tokens
This is where AI adoption changes the conversation.
Ask each software owner to list the tools connected to their account. Include browser extensions, meeting recorders, AI assistants, workflow automations, CRM add-ons, and integrations set up through Zapier-style connectors.
For each connection, document:
- What data can it read?
- What actions can it take?
- Can it send email, create files, edit records, or export data?
- Is access limited to a specific folder, mailbox, team, or client segment?
- Does it hold a token that remains active after the staff member leaves?
- Can the connection be revoked centrally?
A tool that can only read a designated meeting-transcript folder is a different risk from a tool with access to every SharePoint site and every adviser calendar.
The principle is simple. Give agents the smallest useful set of permissions. Don’t give a drafting tool the authority to publish, send, delete, or administer systems unless there is a tightly controlled reason.
4. MFA that actually resists phishing
SMS codes and app-based one-time codes are better than no MFA. They are not always enough against modern phishing.
Attackers can build convincing login pages, capture passwords and codes in real time, and relay them to the real service. AI makes the creation and refinement of those lures faster.
Phishing-resistant MFA uses methods tied to the legitimate website or device, such as FIDO2 security keys or passkeys. These approaches make it much harder for a fake login page to reuse a captured credential.
Start with privileged accounts, then extend to people who can access client records, document repositories, payment information, or large contact lists.
If a full rollout feels too large, don’t let that delay the first move. Protect the ten most consequential accounts first.
5. Data exports and unusual activity
A compromised account often behaves differently before the damage becomes visible.
It may download large numbers of files. It may search for terms like passwords, tax file numbers, identity documents, banking details, or administrator guides. It may grant permissions to a new application. It may create mailbox forwarding rules. It may log in at an unusual time from an unmanaged device.
Your IT provider should be able to tell you what is monitored and what is not. Many firms assume this happens automatically. Sometimes it does not.
You need a clear answer to three questions:
- What alerts are generated for privileged account activity?
- Who receives them and who responds after hours?
- How quickly can you disable an account and revoke connected sessions?
AI agents should reduce work, not widen access
There is a genuine operational opportunity here. Advisers and paraplanners still lose too much time to meeting preparation, document creation, compliance records, and onboarding follow-up.
We commonly see advisers spending 5 to 10 hours a week preparing for client reviews and writing notes after the meeting. Advice documents can consume $3K to $8K of paraplanner cost per document when gathering information, drafting, reviewing, correcting, and chasing missing inputs are included. Client onboarding often takes 30 to 60 days because documents and decisions arrive in fragments.
Those are sensible areas for AI agents. They are also areas where access must be designed carefully.
Take the Meeting Prep Agent (Omni ops). It pulls portfolio data, recent communications, and goal progress into a one-page brief for the adviser before a client meeting.
A poorly configured version might receive broad access to every client record, every mailbox, and every file stored by the firm.
A well-configured version works differently. It uses a service account with limited permissions. It can access the assigned adviser’s upcoming meeting list, approved portfolio data fields, selected CRM records, and recent client communications relevant to that meeting. It creates a draft brief in a controlled folder. It does not send emails, change portfolios, alter CRM records, or access firm-wide administrator settings.
That is how you get the operational benefit without turning an agent into an all-access credential.
The same applies to the Advice Document Agent (Omni ops). This agent can draft SOAs, ROAs, and file notes from meeting transcripts and your compliance template. It should not have permission to approve an advice document, publish it to a client portal, or alter the source template without a human review.
The adviser or authorised paraplanner remains accountable for advice quality, compliance review, and client suitability. The agent removes repetitive assembly work. It doesn’t become an unsupervised decision-maker.
You can see how these controlled workflows are designed through Omni ops, where the focus is on practical operational agents rather than generic AI experiments.
What a secure agent workflow looks like end to end
Consider a new client onboarding process.
A Client Onboarding Agent (Omni ops) runs a guided fact-find, collects KYC documents, follows up on missing items, and prepares a clean onboarding pack for the adviser.
Here is the right sequence.
First, the client enters through a secure invitation. The client receives a time-limited link, not a generic upload folder that can be passed around. The agent collects only the documents and information needed for that onboarding stage.
Second, documents are stored in a client-specific location with access limited to the assigned advisory team. The agent can label files, check completeness, and request a missing document. It cannot browse other client folders.
Third, the agent writes structured information into the CRM or onboarding workflow. It should have permission to create a draft record or update defined fields. It should not have broad rights to export the entire CRM database.
Fourth, the agent creates an onboarding pack for human review. The adviser checks risk profile responses, identification details, source-of-funds information, and any inconsistency that needs a conversation rather than an automated reminder.
Fifth, the audit trail records what the agent accessed, what it created, and what human approved the next step.
This design is not bureaucracy for its own sake. It is the difference between an automation that saves a client service team six hours each week and one that creates a new path into your client records.
The same design discipline applies to meeting notes, advice documents, client communications, and internal research. If an agent doesn’t need a permission to do its job, don’t grant it.
For firms looking at broader operating workflows, Omni advisory is a useful place to understand how process design, controls, and automation fit together.
Put a 30-day access review in motion
You don’t need to solve every security issue in one project. You do need a deadline and an owner.
A sensible 30-day plan looks like this.
Week 1: Name an accountable internal owner. Usually this is a partner, operations manager, or general manager, supported by your IT provider. Build the initial list of systems, privileged accounts, service accounts, shared logins, and connected applications.
Week 2: Remove or disable access for former staff, dormant users, and unnecessary vendors. Change shared administrative credentials where they cannot be retired immediately. Check that offboarding is documented and repeatable.
Week 3: Implement phishing-resistant MFA for administrator accounts and the users with the broadest client-data access. Review conditional access settings, device policies, and recovery methods. Weak recovery paths can undo otherwise strong MFA.
Week 4: Review every AI-connected tool. Revoke connections that have no clear owner or business use. Reduce permissions for the tools you retain. Document the data each tool can access and the human approval points in the workflow.
Then make access review a recurring management process. Quarterly is often appropriate for a firm with regular staff movement, multiple systems, or active AI projects. A small firm with stable staff might start every six months, but privileged access and departing staff should be addressed immediately, not saved for the next review.
If you’re unsure where to begin, Book a 60-min Omni Audit. It is a working session, not a sales deck.
The financial cost is bigger than an IT line item
The annual leakage band for many advisory firms is around $70K to $200K. That doesn’t usually sit in one account called “inefficiency.”
It appears as adviser time spent preparing for meetings. It appears in paraplanner rework and long document cycles. It appears in client onboarding delays that reduce momentum. It appears in manual checks because systems don’t connect cleanly. It also appears in the cost of cleaning up access problems after people, tools, and permissions have accumulated.
Security and productivity are often treated as separate conversations. They shouldn’t be.
A rushed AI rollout can create risk. Refusing to automate can leave a firm carrying manual cost that competitors are steadily removing. The better approach is to build controlled agents around specific bottlenecks, with least-privilege access, approval points, audit trails, and clear ownership.
That gives your team room to focus on client conversations and advice quality, without handing an unnecessary amount of access to every new tool.
Our resources and learning library has material for firms working through the operating side of AI adoption. But the practical starting point is an honest look at your own systems and permissions.
Make the access review part of the AI plan
AI-assisted attackers are changing the speed of compromise. Financial advisory firms cannot rely on the idea that a small team makes them invisible or that existing MFA covers every risk.
Review privileged access. Remove dormant accounts. Move key users to phishing-resistant MFA. Map the integrations attached to your systems. Limit each AI tool to the smallest set of data and actions it needs.
Then build agents where they remove real operational friction.
The Meeting Prep Agent can give advisers a useful pre-meeting brief without reading the entire firm. The Advice Document Agent can shorten drafting cycles without approving advice. The Client Onboarding Agent can reduce back-and-forth without gaining unrestricted CRM access.
That is the standard to aim for.
See Omni for financial advisory firms to understand the audit process. In 60 minutes, we identify the highest-value workflow opportunities, the access and control requirements around them, and a practical next step. No deck. No vague transformation plan.
When you’re ready to put that review in motion, Book my Omni Audit.